Read the full written lesson (~7 min)
What this module is — and what it deliberately isn't
This is not another set of ten questions about ten different facts. It is one story, about twenty minutes long, told in stages. At each stage you'll see what a normal day looks like — an email, a phone call, a message from a colleague, a request from a tool — and you'll choose what to do next. Your earlier choices shape what happens later, the way they would in real life.
There is no way to skim to the end. You cannot pass by memorising answers, because the scenario is built from judgment calls, not trivia. Questions like 'is this always true?' don't apply here — the questions are closer to 'what would you actually do, right now, given what you know at this exact moment?'
The scenario is scaled to your firm's placed AI-use level (from the very first lesson, Level 0 through Level 4). If your firm doesn't yet use AI tools directly, the incident centers on impersonation and scam pressure aimed at your people. If your firm uses AI assistants day to day, the incident also includes a moment where the AI itself offers a suggestion — and part of what's being tested is whether you know that the AI advises and a human still decides.
The scenario: a Monday morning at a small, careful firm
Here is the shape of the story, so nothing feels like a trick when you sit down to do it for real.
- Stage 1 — An odd but plausible email. It looks like it's from a supplier or client you actually work with. Something about it is slightly off — a changed bank detail, an unusual urgency, a request to skip the normal approval step 'just this once.' You decide what to check before doing anything.
- Stage 2 — A follow-up phone call. Someone calls, sounding exactly like a real contact — maybe even a voice you recognise. They reference the email and push for a faster answer. You decide how to verify who you're actually speaking to, without being rude or accusatory.
- Stage 3 — Pressure and a deadline. You're told the payment, document, or decision needs to happen in the next few minutes or something bad will happen — a shipment missed, a client lost, a fee incurred. You decide whether urgency is a reason to skip a check, or exactly the reason to slow down.
- Stage 4 — A tool offers help. If your firm uses an AI assistant, it drafts a reply, summarises the thread, or suggests an action. You decide what you check before you accept its suggestion — and what you still do yourself.
- Stage 5 — Closing it out. You decide what to record, who to tell, and whether this becomes 'nothing, false alarm' or 'we caught something, and here's what we changed.'
Every stage is drawn from real, documented cases used earlier in this course — invoice fraud, voice-cloned calls, urgency-based scams, and over-trusting an AI's confident-sounding output. Nothing here is invented to catch you out; it's assembled from things that have actually happened to firms like yours.
How you're scored: the judgment rubric
You are not scored on whether you got 'the' answer, because several reasonable paths through this scenario exist. You are scored on four things, each worth part of your final result:
- Verification before action (35%). Did you confirm who or what you were really dealing with — through a second channel, a known contact number, a separate check — before doing something that can't be undone (paying, sharing, approving, deleting)?
- Appropriate pace under pressure (25%). Did urgency change what you checked, or just how fast you checked it? Slowing down for thirty seconds to confirm is always acceptable; skipping the confirmation because you were told to hurry is the failure mode this measures.
- Correct escalation (25%). Did you loop in the right person — a manager, IT contact, or named decision-owner — at the point a reasonable person would, rather than either escalating everything (which wastes trust) or nothing (which is the actual danger)?
- AI-output handling, where relevant (15%). If a tool offered a suggestion, did you treat it as a draft to check, not a decision to accept? This section only counts if your firm's level includes AI-assisted steps.
There is a pass threshold, and it is set high enough to mean something — this is deliberately harder to 'accidentally' pass than the per-lesson quizzes were. If a step goes badly, the story continues realistically (the way a real mistake would play out), and later stages still let you demonstrate good judgment — one bad decision does not automatically fail the whole certificate.
Your certificate: what it proves, and how long it lasts
Passing produces a Certificate of AI Safety Literacy with your name, the date, the course version it was issued under, and your firm's name. It is not a 'completed the course' badge — it specifically states that you demonstrated end-to-end judgment on a realistic incident, scored against a fixed rubric, not just that you clicked through the lessons.
The certificate is valid for 12 months. That isn't bureaucracy for its own sake — scams, tools, and the tricks people use to sound convincing all change over the course of a year, and a certificate that never expires stops meaning anything after a while. At renewal, you'll do a shorter refreshed version of this same scenario, updated with whatever has changed since you last took it.
Practically, this certificate is meant to be something your firm can actually use: attached to an insurance renewal, shown to a regulator or auditor, referenced in a client contract, or simply kept on file as evidence that your team was trained on judgment, not just facts — which is exactly the kind of evidence bodies like insurers and regulators (including under emerging AI-literacy rules) are starting to ask for.
If you don't pass on the first attempt
This is deliberately the hardest part of the course, and not passing first time is common and not a black mark. You'll see exactly which of the four scored areas held you back — not just a raw score — so you know precisely what to revisit. You can return to the specific lesson modules connected to that weak area, and then retake the scenario. There is no limit on attempts and no waiting period built in for punishment; the only requirement is that you actually revisit the material, because retaking the same scenario without reviewing anything rarely changes the outcome.
One thing worth saying plainly: the goal of this module is not to make anyone feel foolish. It exists because the two or three minutes when a scam is actually happening to you feel completely different from reading about scams afterwards. Practising the decision now, in a safe walkthrough, is what makes the real version easier to get right later.